We actively monitor and provide security patches for the following versions of Glyph. If you are running an unsupported version, we highly recommend upgrading to the latest release to ensure your environment remains secure.
| Version | Supported |
|---|---|
| x.1.x | ✅ |
| < 0.1.0 | ❌ |
We take the security of our tools seriously. If you believe you have found a security vulnerability in Glyph, please follow the steps below to report it responsibly.
Do not open a public GitHub issue for security vulnerabilities. Instead, please report them via one of the following methods:
- GitHub Private Reporting: Use the Private Vulnerability Reporting feature on this repository.
- Email: Send a detailed report to the maintainer via the contact information on the xenios91 profile.
To help us triage the issue quickly, please include:
- A detailed description of the vulnerability.
- Steps to reproduce the issue (proof-of-concept code or scripts are highly encouraged).
- An assessment of the potential impact.
- Acknowledgement: You can expect an initial response within 72 hours of your report.
- Updates: We will provide progress updates at least once a week while the issue is being investigated.
- Public Disclosure: Once a fix is verified and released, we will coordinate a public disclosure/security advisory. We kindly ask that you refrain from disclosing the vulnerability publicly until a patch has been made available.